
Help Me With HIPAA
597 episodes — Page 6 of 12
Ep 334Secure Your SaaS - Ep 334
SaaS continues to grow as a popular way to deploy business applications. It is crucial for businesses to understand what data they are storing in their SaaS cloud applications and how to protect it from data breaches. So, listen to us discuss securing your SaaS. More info at HelpMeWithHIPAA.com/334
Ep 333Taking the Team Approach to Privacy and Security - Ep 333
Protecting your company's data is no longer optional. With so many changes in how people work today and where they are working from, keeping a low profile when it comes to protecting data won't cut it anymore. Today, we review a recent report released by Shred-it, a secure information destruction company, called Data Protection Report 2021. More info at HelpMeWithHIPAA.com/333
Ep 332HMWH Thanksgiving Team Discussion - Ep 332
For the Thanksgiving episode this year, we talk to the Kardon Team about the recent social engineering attack; a follow up from our Halloween episode, We Are Under Attack - Ep 328. We find out what they experienced and how they felt during and after the attack. And, because it's Thanksgiving, we each share what we are thankful for in 2021. More info at HelpMeWithHIPAA.com/332
Ep 331Secure Your Legacy - Ep 331
Use of legacy software and devices plague healthcare. OCR's recent newsletter focuses on why legacy systems are still used in healthcare organizations and provides guidance on ways to manage the risks of these systems. More info at HelpMeWithHIPAA.com/331
Ep 330Don't forget about the SAG! - Ep 330
The HITECH Act added that state attorney generals can take on cases on behalf of their constituents under HIPAA. We haven't seen that many cases from the states thus far, but that may be changing. Today we discuss a recent New Jersey case regarding fraud, deceit, misrepresentation and professional misconduct. This is an eye opening state level case that everyone should pay attention to. More info at HelpMeWithHIPAA.com/330
Ep 329Do you audit your EHR logs? - Ep 329
Insider threats are dangerous for any organization, not just healthcare. As a result, healthcare organizations need to be extra vigilant when it comes to protecting patient data. Today, we talk with Ray Ribble, CEO of SPHER, to hear some stories about why it's important to review EHR logs and how his company can help you identify potential insider threats. More info at HelpMeWithHIPAA.com/329
Ep 328We are under attack! - Ep 328
It's time for our annual Halloween episode! This year we will tell you a scary, true story of how our two companies were actively targeted and attacked by a cybercriminal. Hear what happened and how our teams reacted to the cyber attack. More info at HelpMeWithHIPAA.com/328
Ep 327CISA Interview - Ep 327
In today's episode, we talk with Josh Corman, Chief Strategist Cybersecurity and Infrastructure Security Agency (CISA) at the Department of Homeland Security. We will learn about CISA and what information and freely available services they provide to help healthcare businesses and other organizations within the nation's 16 critical infrastructure sectors from cyber attacks. More info at HelpMeWithHIPAA.com/327
Ep 326Is email evil? - Ep 326
Email is a great tool for communication. It is quick, simple, and it has the potential to reach so many people in so little time. But, it can also be an easy way for hackers to get their hands on your personal information if you're not being careful. Phishing scams are one of the most popular ways that hackers use email as a tool to steal your information and cause data breaches. Email is evil! More info at HelpMeWithHIPAA.com/326
Ep 325IT and cybersecurity are not the same - Ep 325
IT and cybersecurity services are not the same. If you are in the market to purchase managed services or security services from an IT firm, you'll want to listen to this podcast to understand how they are different, why they are different and why you need to understand those differences to better protect your organization from cyber attacks. More info at HelpMeWithHIPAA.com/325
Ep 324Insights for Customers of MSPs - CISA - Ep 324
In a world where people are more dependent on technology but lack the expertise to manage their own networks and systems effectively and efficiently, they turn to Managed Service Providers (MSPs). CISA has released a guide, Risk Considerations For Managed Service Provider Customers, that outlines risk considerations organizations need to consider when they partner with a MSP. We will cover this in today's episode and we are making a big announcement that you'll want to hear. More info at HelpMeWithHIPAA.com/324
Ep 323Consider 3 Ransomware Stories - Ep 323
There are many challenges that come with preparing for and responding to a ransomware attack. Ransomware gangs are constantly changing their tactics in order to get to your organization's data. Therefore, as the ransomware landscape continues to evolve, so too must the preparations and responses of businesses. More info at HelpMeWithHIPAA.com/323
Ep 322ASPR TRACIE - Readiness and Response Planning - Ep 322
You know how we love to pass along guides and resources that can help you improve your organization's privacy and security programs. Today, we are going to review a recent resource guide put out by HHS' ASPR TRACIE office called Healthcare System Cybersecurity - Readiness and Response Considerations. This guide is packed with very helpful tips, best practices, and resources surrounding cybersecurity and responding to cyber incidents. And it's FREE! More info at HelpMeWithHIPAA.com/322
Ep 3217 HIPAA Facts - Ep 321
Social media is full of people who speak "confidently" about topics that they simply do not fully understand. HIPAA is one of those topics. Today, we are covering 7 HIPAA facts that we hope will set the record straight about frequently misunderstood HIPAA topics. More at HelpMeWithHIPAA.com/321
Ep 320Social Engineering Tricks with William Price - Ep 320
Learn 'tricks of the trade' from a real social engineering tester. We interview William Price of Cyberx.tech to learn how they are able to successfully penetrate a company's defenses and get access to their most critical information. How likely would your organization be vulnerable to these same methods? More info at HelpMeWithHIPAA.com/320
Ep 319Don't Be An ID10T! - Ep 319
Have you ever heard tech folks refer to a computer problem as an ID10T error? You probably thought it was some highly technical term geeks use. Well, it's not and today we are going to talk about a couple posts and articles where folks' are flying their ID10T flag high and proud. And hopefully try to prevent you from making an ID10T error. More info at HelpMeWithHIPAA.com/319
Ep 3182021 #BeCyberSmart - Ep 318
It's that time of year again. Time to start preparing for National Cybersecurity Awareness Month coming up in October. Do Your Part. #BeCyberSmart is the theme again this year. Be a Cybersecurity Awareness Month Champion for your business, your community and your family. More info at HelpMeWithHIPAA.com/318
Ep 3176 Steps for Vendor Management - Ep 317
Managing your vendors, or your supply chain, has become increasingly more important these days. As we've seen in the news just in the last several months, data and system breaches can come as a result of the vendors you work with. So, we felt like it was time to revisit this topic by reviewing the recent update to the HIC SCRiM guide that includes 6 steps for vendor management. More info at HelpMeWithHIPAA.com/317
Ep 3162021 Data Breach Cost Report - Ep 316
Every year we cover the most recent report released on the cost of a data breach. No surprise from this year's report that the cost continues to rise. And healthcare breaches cost the most across all industries. Listen in as we go through IBM's Cost of Data Breach Report 2021. More info at HelpMeWithHIPAA.com/316
Ep 315New Breach Notification Bill - Ep 315
There's a new data breach notification bill in Congress that will affect the business community as a whole, not just healthcare. It will create a new data breach disclosure requirement for federal agencies, federal contractors and critical infrastructure companies. It's time to let folks know when breaches happen. We can't protect ourselves from things we don't know about. More info at HelpMeWithHIPAA.com/315
Ep 314Cyber Sqwerl - Ep 314
There is so much happening in the cyber world today that we couldn't decide on just one topic to cover in this episode. So, we will be jumping around and covering a lot of different cyber topics, hence the title of the podcast, Cyber Sqwerl. So, listen fast folks… we've got a lot to cover. More info at HelpMeWithHIPAA.com/314
Ep 313MSPs Attacked Again - Ep 313
Summertime, holidays and long weekends, where many of us are taking time off, are prime times for cyber attacks. The bad guys are counting on people being in a hurry and letting their guard down so it'll make it easier to suck you into their attack. July 4th 2021 was no different. An MSP was attacked by cyber criminals. Although this is still an active incident, we will cover what we know in today's podcast. More info at HelpMeWithHIPAA.com/313
Ep 312Offshore or Not? - Ep 312
Offshore services are a popular option for many businesses. The ability to work around the clock from different sides of the planet is one thing but the cost savings are the primary driving force for this solution. When it comes to HIPAA Business Associates, though, there are a lot of variables that must be considered when deciding whether to offshore or not. More at HelpMeWithHIPAA.com/312
Ep 311SMB Security Best Bets - Ep 311
Securing your business is not always the easiest thing to do nor the cheapest. Today we will review a Cisco study on small and medium sized businesses and their security best bets. In other words, the things that you can do that will help you to most likely attain success and get you the most bang for your buck. More info at HelpMeWithHIPAA.com/311
Ep 310DOL Cybersecurity Guidance - Ep 310
The Department of Labor (DOL) Employee Benefits Security Administration (EBSA) issued its very first cybersecurity guidance in April 2021and they sound remarkably like all the things that we recommend doing under HIPAA, HICP and the NIST cybersecurity framework. Let's check it out! More info at HelpMeWithHIPAA.com/310
Ep 309Is it really that bad? - Ep 309
They say ignorance is bliss. Ignorance can also leave you vulnerable to cyber attacks and patient safety issues. As we see news about cyber attacks coming from everywhere, you might ask "Is it really that bad?" Yes, yes it is. And it continues to get worse. More info at HelpMeWithHIPAA.com/309
Ep 308Maturity Model Matters - Ep 308
Privacy and security should be a part of all organizations day-to-day activity and company culture. But how do you know how mature your privacy and security program really is? By using one of the many maturity models. Today, we are discussing the new DoD Cybersecurity Maturity Model Certification (CMMC) that breaks controls into levels so you can see what implementation level or maturity level your program is at any given moment. More info at HelpMeWithHIPAA.com/308
Ep 307Peachstate Not A Peachy OCR Settlement - Ep 307
It's been a while since we've reviewed an OCR settlement that wasn't about the patient right of access initiative. Things are a changin', and in more ways than one. OCR announced the Peachstate settlement just this week that got our attention. How this case ended up being investigated in the first place is interesting. And as usual, the headline doesn't tell the whole story. So, let's dive in and check it out. More info at HelpMeWithHIPAA.com/307
Ep 3066 Points In Cyber Executive Order - Ep 306
One of the biggest security problems on the Internet is a ransomware attack. Ransomware can impact all our lives. Just take the Scripps Health and Colonial Pipeline ransomware attacks that we discussed in recent podcast episodes. Last week we gave you 6 tips for planning for a ransomware attack. And today we are going to discuss 6 points from the recently released cybersecurity Executive Order. More info at HelpMeWithHIPAA.com/306
Ep 3056 Ransomware Planning Tips - Ep 305
Ransomware is just not going away. Falling victim to a ransomware attack will have a BIG impact on you, your business, your clients and your patients. So, today we share some ransomware planning tips. It's important to know what things you should be doing and should at least consider so that you don't get caught with your proverbial "pants down." More info at HelpMeWithHIPAA.com/305
Ep 304Privacy Questions Everywhere - Ep 304
We've talked about how damaging a ransomware attack can be in healthcare, not only for the practice or health facility but also for patients and the integrity and availability of their data. Today, we discuss an active ransomware attack affecting a health system that is not just making the local news, but also is blowing up on social media and creating a number of privacy concerns. The implications for their patients is terrifying. More info at HelpMeWithHIPAA.com/304
Ep 303HIPAA Compliant Apps - Ep 303
We've all seen the websites of companies that claim to have a "HIPAA compliant" app, product or service. But does that really mean anything? The short answer is NO! There is no such thing. Today, we answer a listener question about products and services with these types of claims. And, as you can imagine, we have a lot to say about this topic. More info at HelpMeWithHIPAA.com/303
Ep 302Get Your Patch On - Ep 302
We talk about patching pretty frequently on the podcast, but there is still a misconception that your IT or MSP team is patching everything. Systems are not designed to patch all hardware and software all of the time. There is a level of responsibility that falls on us to understand what is being patched by IT, what isn't and what we do about those unpatched applications. More info at HelpMeWithHIPAA.com/302
Ep 301What is Basic Cyber Hygiene - Ep 301
Basic Cyber Hygiene is a fairly new term, but I realized we have mentioned it several times over the last few weeks. What do we really intend people to see when we talk about it? That may be helpful if we think it would solve most of our cyber attack problems, huh. More info at HelpMeWithHIPAA.com/301
Ep 300Caveat Discussion - Data Privacy and Security - Ep 300
Hard to believe that this is our official 300th episode! We are still a tiny podcast in a huge sea but we are pretty sure you can not find a longer running podcast about HIPAA Privacy and Security. To celebrate we have some very special guests, Dave Bittner and Ben Yellen from the CyberWire Caveat podcast. They are joining us for a discussion about where we all see things going in the future for data privacy laws and cybersecurity protections. More info at HelpMeWithHIPAA.com/300
Ep 299HIPAA Summit 2021 News Part 2 - Ep 299
Each year the National HIPAA Summit 2021 is a regular event for us. It was held last year just before the shutdown. The event this year was loaded with discussions about what had happened in the previous 12 months and the massive list of things happening in the next 12 months. That is A LOT of HIPAA! Today we cover part 2 of news of note from the conference. More at HelpMeWithHIPAA.com/299
Ep 298HIPAA Summit 2021 News Part 1 - Ep 298
If you are a regular listener of the podcast, you know how Donna loves to "HIPAA-geek out" over the HIPAA Summit each year. Things are no different this year as the virtual conference stretched 3 full days and another half day. Needless to say Donna got TONS of information to share - so much so we won't be able to fit it all in this one podcast. So, let's get to Part 1 of the HIPAA Summit 2021. More info at HelpMeWithHIPAA.com/298
Ep 297Courts, Cameras, and Exchange - Ep 297
Cyber attacks keep on coming and there is no expectation that they'll ever stop. Attacks are coming from everywhere - vulnerabilities in software applications, insecure IoT devices connected on the internet, email attacks and phishing, etc. Protecting your systems from cyber attacks is not a "one and done," "set it and forget it" project. It is a critical and continuous business process that every organization must address. And, surprise surprise, it also requires vetting your vendors as many attacks are coming through your supply chain. More info at HelpMeWithHIPAA.com/297
Ep 296Evaluating Cyber Threats 2020 to 2021 - Ep 296
Reports are coming out evaluating cyber threats with stats and details documenting the aftermath of attacks happening in 2020 and the outlook for 2021. Let's just say they are all on brand with what you expect from anything related to 2020. As you can guess, it isn't looking good for 2021 based on where we are right now. We reviewed some of the articles and reports evaluating cyber threats so you don't have to... unless you must. More at HelpMeWithHIPAA.com/296
Ep 295Little Things Matter - Ep 295
Isn't it always the little things that make a big difference? That's true not only in life, but also when it comes to protecting your data and network from attacks. And, it is often the small things that when overlooked can become a big problem. So, today we are talking about some of the things that you need to be looking for and that can make a big difference in your privacy and security programs. For more info HelpMeWithHIPAA.com/295
Ep 294PACS Exposed Part 2 - Ep 294
Supply chain cyber threats are happening so often it seems like they keep showing up in the news daily. The list of cases keeps growing every month. So much is still slowly being learned about the SolarWinds attack it is getting hard to keep up with how far it goes. Now we have water systems and more healthcare breaches trickling in. This week I even saw a case we covered before about exposed PACS images. It's time for us to talk about what these supply chain attacks mean to the rest of us. For more info HelpMeWithHIPAA.com/294
Ep 293Supply Chain Cyber Threats Getting Real - Ep 293
Supply chain cyber threats are happening so often they keep showing up in the news. The list keeps growing every month. So much is still slowly being learned about the SolarWinds attack it is getting hard to keep up. Now we have water systems and more healthcare breaches trickling in. It's time for us to talk about what these supply chain attacks mean to the rest of us. More at HelpMeWithHIPAA.com/293
Ep 2929 Smart Cyber Habits - Ep 292
Smart cyber habits are part of a new initiative introduced by CISA they have titled Reduce the Risk of Ransomware Awareness Campaign that will be running for a new month now. The campaign includes a lot of great educational information and a toolkit among other things they have planned. Certainly worth us sharing with you guys because you can't have too many chances to find something that will connect with leadership or your workforce. More at HelpMeWithHIPAA.com/292
Ep 291Privacy Rule Proposed Changes - Ep 291
HHS's Office for Civil Rights published their proposed changes to the HIPAA Privacy Rule. The changes include some required to make HIPAA better align with the requirements of 21st Century Cures Act for patient access to their records. There's a few other changes to note, as well. Let's check them out, shall we? More into at HelpMeWithHIPAA.com/291
Ep 290Phishing Test Report - Ep 290
During NCSAM Kardon signed up for the Terranova Phishing Tournament - much to everyone's surprise. Great news is we didn't have anyone clicking on the link. What did they learn in the tournament? More at HelpMeWithHIPAA.com/290
Ep 289OCR Enforcement News - Ep 289
The OCR enforcement announcements keep coming. Our reviews of not only the new announcements but news on some of the older ones are the topic for today. Did you know one from 2018 is still being reviewed in the courts while we get new ones already in 2021? More at HelpMeWithHIPAA.com/289
Ep 288Cyber Liability Trends with John Miller - Ep 288
Always great to talk cybersecurity insurance coverage with John Miller of Sterling Seacrest Partners. Threats are constantly evolving for all of us. That means cyber liability coverage must also evolve. Have you evaluated what your cyber policy will really cover when you are attacked? There are certainly several areas John brings up for us all to consider in our cybersecurity policies. More info at HelpMeWithHIPAA.com/288
Ep 28710 2021 Predictions Plus 2020 Results - Ep 287
Making annual predictions is always a little bit guessing and a lot of luck by the end of the year. No way any of us could have predicted where we would go throughout the year we just call 2020. Only history will tell us will give us the distance to understand the last 12 months. Who knows where we will go next but what the umm heck. We figured we would do it again. More info at HelpMeWithHIPAA.com/287
Ep 286New HIPAA Safe Harbor - Ep 286
A new HIPAA safe harbor rule is out there floating around now. A safe harbor is a legal term that refers to laws and regulations that specify that certain actions will be considered not to violate a given rule. It is often used to clarify big standards like HIPAA. Encryption is one of those things under the breach rules. Do you know about HR 7898? More at HelpMeWithHIPAA/286
Ep 285Cyber Attacks Will Get Worse In 2021 - Ep 285
A hospital President, after being hit by a cyber attack, said "We really did not anticipate the scope or the impact the attack had on our system and how far-reaching it was." This is just the beginning. Get prepared for more to come. Especially, with the success of the major SolarWinds infiltration. We knew things were getting worse weeks ago when we recorded this one. Where do we see things going? More at HelpMeWithHIPAA.com/285